Adding a Remote Node Record to the Parameter File Manually for the SSL or TLS Protocol
About this task
Refer to the Remote Node Security Feature Definition Worksheet that you created for the remote node you are adding when you complete this procedure. The following procedure assumes that this remote node uses the SSL or TLS protocol and client authentication with Connect:Direct® Secure Plus unless you want to override the IBM Connect:Direct Secure Plus parameter settings from the PROCESS statement. For more information, see Override Settings in IBM Connect:Direct Processes.
To add a remote node record manually for the SSL or TLS protocol:
Procedure
-
On the Option line type I (Insert Node) on the
Secure+ Admin Tool Main Screen and press Enter to add
a node. The Secure+ Create/Update Panel displays.
File Edit Help ------------------------------------------------------------------------------- Secure+ Admin Tool: Main Screen Row 1 of 1 Option ===> Scroll CSR Table Line Commands are: U Update node H View History D Delete node I Insert node V View node CL Clone node Node Filter : * Secure+ External Client LC Node Name Type Protocol Override Encryption Auth Auth -- ---------------- ---- -------- -------- ---------- -------- -------- I MY_LOCAL L TLSV13 Y Y N Y ******************************* BOTTOM OF DATA ******************************** -
On the Secure+ Create/Update Panel:
- In the Node Name field, type the name for the remote node that corresponds to its name in the network map.
-
Type R in the Type (Local or Remote) field.
CMD Secure+ Create/Update Panel Option ===> Node Name: MY.REMOTE Type: R (Local or Remote) -------------------------------------------------------------------------- | Security Options | EA Parameters | SSL/TLS Parameters | | --- -- --- | -------------------------------------------------------------------------- Secure+ Protocol: Security Mode (Yes No Default to Local) Enable SSL D Enable FIPS Enable TLS 1.0 D Enable SP800-131a Transition D Enable TLS 1.1 D Enable SP800-131a Strict D Enable TLS 1.2 D Enable NSA Suite B 128 bit D Enable TLS 1.3 D Enable NSA Suite B 192 bit D Auth Timeout: 120 Enable Override D Alias Names: TCP Information: IPaddr: Port: OK Cancel
-
SSL being an older protocol is no more available for selection from
Connect:Direct version 6.3. To implement SSL with version 6.2 and below, do one
of the following, depending on whether you want to use SSL for all data
Transfers or on a Process-by-Process basis:
- Type Y beside the Enable SSL field to enable the SSL protocol for this remote node.
- Type N beside the Enable SSL field to disable the SSL protocol.
Note: SSL cannot be enabled for version 6.3 of Connect:Direct. Once disabled while updating the Secure Plus Parameter File, SSL cannot be enabled again. -
TLS 1.0 and TLS 1.1 are no more available for selection from Connect:Direct
version 6.3. To implement TLS 1.2, do one of the following, depending on whether
you want to use TLS for all the data transfers or on a Process-by-Process
basis:
- Type Y beside the Enable TLS 1.2 field to enable the TLS protocol for this remote node. Repeat for TLS 1.3.
-
Type N beside the Enable TLS
1.2 field to disable the TLS 1.2 protocol.
Note: TLS 1.0 and TLS 1.1 cannot be enabled for version 6.3 of Connect:Direct. Once disabled while updating the Secure Plus Parameter File, these protocols cannot be enabled again.
-
In the Security Mode field, type Y, N, or D to enable or disable
multiple protocolssuch as, FIPS, SP800-131a and NSA Suite B.
- Alias Names field do not apply to remote node. This field should be left blank.
- TCP Information fields (IP addr and Port) do not apply to remote node. This field should be left blank.
-
Depending on whether you want to use the Connect:Direct Secure Plus parameter settings override
feature, type Y to enable or N to disable beside the
Override field. Enabling Override for the Remote record allows not only the
Process to override the security settings but also allows the SNODE to override the security
setting. Use caution when enabling this option on the Remote record to override any setting defined
in the Local node record
.
-
Select the SSL/TLS parameters panel by typing SSL
and press Enter to display the Secure+ Create/Update
panel:
CMD Secure+ Create/Update Panel Option ===> Node Name: CD.ZOS.USER2 Type: R (Local or Remote) -------------------------------------------------------------------------- Security Options | EA Parameters | SSL/TLS Parameters | --- -- --- | -------------------------------------------------------------------------- Enable Client Auth N (Yes No Default to Local) Enable Data Encrypt D (Ignored Forced to Y) Cipher Selection Method MANUAL (Extended Manual) ------------------------------------------- Certificate Label | * | Cipher Suites | FFFF | Certificate Pathname | * | Certificate Common Name | | ------------------------------------------- OK Cancel -- --- - To implement Client Authentication, type Y for enable or N to disable beside the Client Auth. Since, Data Encryption field (Enable Data Encrypt) has been deprecated from release 6.2, it will not be effective on process though user can change it in secure parmfile. It always will work as Enable.
-
Select Certificate Label field by placing the cursor on the text and
press Enter. On the entry panel specify the Certificate Label as defined in
the certificate or leave blank to use the default certificate defined in the key database or key
ring. Leaving the certificate label blank will generate a warning message up on saving the parameter
file. This is meant as a warning that the key store must define a default certificate. Select the
Certificate Label field and press Enter.
Note: The Certificate label field is automatically set to '*' (Default to Local) in the Remote Node record. You are not allowed to update this field for a remote node.
- Certificate Pathname does not apply to a remote node. This field should be left blank
-
Select Cipher Suites by placing the cursor on the text and press
Enter.
Extended or Manual cipher suite selection panel will open according to Cipher selection method field.
-
Manual Panel:
- To select ciphers, order the list in All Available Cipher-Suites by placing them 1 through n (maximum of 10).
- As ciphers are selected they move to the Enabled Cipher-Suites on
the right side. This list is the default cipher list.
This is a scrollable panel so use the F8 key to more forward and F7 to move back.
Option ---> Cipher Filtering:Protocol Cipher Sorting:Strongest Update the order field below to enable and order Cipher Suites O All Available Cipher Suites Enabled Cipher Suites == ==================================== ==================================== More: + 1 TLS_AES_256_GCM_SHA384 TLS_AES_256_GCM_SHA384 2 TLS_AES_128_GCM_SHA256 TLS_AES_128_GCM_SHA256 3 TLS_ECDHE_ECDSA_W_AES_256_GCM_SHA384 TLS_ECDHE_ECDSA_W_AES_256_GCM_SHA384 4 TLS_ECDHE_ECDSA_W_AES_256_CBC_SHA384 TLS_ECDHE_ECDSA_W_AES_256_CBC_SHA384 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA TLS_ECDHE_ECDSA_W_AES_128_CBC_SHA256 TLS_ECDHE_ECDSA_W_AES_128_GCM_SHA256 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA TLS_ECDHE_ECDSA_WITH_RC4_128_SHA TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA TLS_ECDHE_ECDSA_WITH_NULL_SHA TLS_ECDHE_RSA_WIT_AES_256_GCM_SHA384 TLS_ECDHE_RSA_WIT_AES_256_CBC_SHA384 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA TLS_ECDHE_RSA_WIT_AES_128_GCM_SHA256 TLS_ECDHE_RSA_WIT_AES_128_CBC_SHA256 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA TLS_ECDHE_RSA_WITH_RC4_128_SHA -
Extended panel:
- Node Name:
- Displays the node name being updated.
- (L/R):
- Indicates whether the node is Local (L) or Remote (R).
- Panel Name:
- "Secure + Extended Cipher Suite" is the name for panel DGA@P141.
- Selection and Filtration Display:
- Displays the number of selected ciphers, the number passing filtration, and the total number available.
- Selection:
- These options are used to select the ciphers by protocol. A selected cipher is pink and
has a number in the ‘O’ column. There are 3 fields available, and for each field the valid
values are 1-99 and ALL:
- ANY:
- Allows the selection of cipher suites for any protocol, either a maximum number, or all that are available.
- TLS12:
- Allows the selection of cipher suites that are supported by TLS12, either a maximum number, or all that are available. This field will be enabled if either the Cipher Filtering field is set to None (N) or if the TLS12 protocol is enabled on panel DMADP126 (Secure+ Create/Update Panel). Otherwise it will be disabled.
- TLS13:
- Allows the selection of cipher suites that are supported by TLS13, either a maximum number, or all that are available. This field will be enabled if either the Cipher Filtering field is set to None (N) or if the TLS13 protocol is enabled on panel DMADP126 (Secure+ Create/Update Panel). Otherwise it will be disabled.
Note: If all of the above Selection fields are blank, then the cipher suites are selected manually by numbering them 1-n (maximum of 99).Note: If any of the above Selection fields are not blank, then all the cipher suites for that field are automatically selected and numbered from 1 to n according to the settings in the Cipher Filtering and Sorting fields as described below.- Cipher Filtering and Sorting:
- These options provide the ability to sort and filter the cipher suite list.
- Cipher Filtering:
- Allows filtering the cipher list by the protocols selected in panel DMADP126 (Secure+ Create/Update Panel). Valid values are P and N. When P is specified then only cipher suites supported by the protocols selected in DMADP126 will be listed. When N is specified, DMADP126 does not influence the cipher suite selection list.
- Cipher Sorting:
- Allows the user to sort the available ciphers. If all Selection fields are blank,
only unselected cipher suites are sorted. If any Selection field is non-blank then all
cipher suites are sorted. The following options are available:
- SA:
- Strength Ascending (refer Understanding of Cipher Suite strength on page 796 on cipher strength)
- SD:
- Strength Descending (refer to Understanding of Cipher Suite strength on page 796 on cipher strength)
- #A
- Numeric(4-byte number for cipher) cipher name Ascending.
- #D:
- Numeric(4-byte number for cipher) cipher name Descending.
- NA:
- Alphabetic cipher name Ascending
- ND:
- Alphabetic cipher name Descending
- RSA:
- Y forces display of all RSA algorithm supported cipher suites, regardless of any other setting.
- ECDSA:
- Y forces display of all ECDSA algorithm supported cipher suites, regardless of any other setting.
This is a scrollable panel. Use the F8 key to more forward and F7 to move back.
CD.ZOS.USER1 (R) Secure+ Extended Cipher Suite 0 Select 35 Filter 35 Total Option ===> Selection: Sorting & Filtering Any (nn ALL) Cipher Filtering N (Protocol or None) TLS12 (nn ALL) Cipher Sorting SD (#A #D NA ND SA SD) TLS13 (nn ALL) RSA N (Y or N) ECDSA N (Y or N) Cipher Suite TLS FI Key O # Name 13 12 PS Size == ==== ===================================================== == == == ==== 1 1302 TLS_AES_256_GCM_SHA384 X 256 2 1301 TLS_AES_128_GCM_SHA256 X 128 C02C TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 X X 256 C024 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 X X 256 C00A TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA X X 256 C02B TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 X X 128 C023 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 X X 256 C009 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA X X 128 C007 TLS_ECDHE_ECDSA_WITH_RC4_128_SHA X 128 C008 TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA X X 168 C006 TLS_ECDHE_ECDSA_WITH_NULL_SHA X C030 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 X X 256 C028 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 X X 256 C014 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA X X 256 C02F TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 X X 128 C027 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 X X 128 C013 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA X X 128 C011 TLS_ECDHE_RSA_WITH_RC4_128_SHA X 128 C012 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA X X 168 C010 TLS_ECDHE_RSA_WITH_NULL_SHA X 009D TLS_RSA_WITH_AES_256_GCM_SHA384 X X 256 003D TLS_RSA_WITH_AES_256_CBC_SHA256 X X 256 0035 TLS_RSA_WITH_AES_256_CBC_SHA X X 256 009C TLS_RSA_WITH_AES_128_GCM_SHA256 X X 128 003C TLS_RSA_WITH_AES_128_CBC_SHA256 X X 128 002F TLS_RSA_WITH_AES_128_CBC_SHA X X 128 000A TLS_RSA_WITH_3DES_EDE_CBC_SHA X X 168 0009 TLS_RSA_WITH_DES_CBC_SHA 56 003B TLS_RSA_WITH_NULL_SHA256 X 0006 TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 *DEPRECATED* 40 0005 TLS_RSA_WITH_RC4_128_SHA *DEPRECATED* X 128 0004 TLS_RSA_WITH_RC4_128_MD5 *DEPRECATED* 128 0003 TLS_RSA_EXPORT_WITH_RC4_40_MD5 *DEPRECATED* 40 0002 TLS_RSA_WITH_NULL_SHA *DEPRECATED* X 0001 TLS_RSA_WITH_NULL_MD5 *DEPRECATED*Note: DEFAULT_TO_LOCAL_NODE does not apply to the Local node record.Note: Select Ciphers carefully since deprecated ciphers may not be available on all systems. Check with your Security Administrator before selecting these ciphers.Note: The Extended Cipher Suite list will show additional information such as which ciphers support which protocols, support FIPS and the key sizes of the ciphers. For more information, see Cipher Selection Rules.
-
Manual Panel:
-
Select the EA parameters option from the panel selection bar and press
Enter to display the EA parameters panel.
Secure+ Create/Update Panel <Change Pending> Option ===> Node Name: MY.REMOTE Type: R (Local or Remote) -------------------------------------------------------------------------- | Security Options | EA Parameters | SSL/TLS Parameters | | --- -- --- | -------------------------------------------------------------------------- Enable External Auth N (Yes , No , Default to Local) External Auth Server Def External Auth Server Address External Auth Server Port OK Cancel -- --- -
To implement the External Authentication Server application:
- Type N in the External Auth field to disable External Authentication Server application.
- Type Y in the External Auth field to enable External Authentication Server application
- External Auth Server Def, External Auth Server Address, and External Auth Server Port are unavailable because they are valid only for the .EASERVER remote node record.
- Select OK and press Enter to display the values for the local node record.
- Using the Save As or Save Active option displays error and warning messages. Read all warning and error messages. Continue configuring the environment without resolving warning messages, but resolve errors before you save the parameter file.
- After you configure the remote node record, you can save and submit the parameter file using the procedures in IBM Connect:Direct Secure Plus Operation Enablement and Validation, but if you have not added a remote node record, connections are not secure.